RUSTSEC-2026-0315Medium· 5.7▾ Sunlit`call_ref` and exception `catch` can drop some fuel accounting, leading to exponential fuel amplification
▾ Sunlit zone — Low / medium · no exploitation signal
impact 31.4 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-m63x-6p34-q65x For more information see the GitHub-hosted security advisory.
wasmtime >= 49.0.0, < 49.0.1Upgrade to a patched release:
wasmtime 49.0.1Connected by shared product, vendor, weakness, or advisory.
RUSTSEC-2026-0316NoneDynamic record lifting can allocate beyond the hostcall fuel limit
RUSTSEC-2026-0269NoneFilesystem sandbox escape when paths or symlinks contain trailing slashes
RUSTSEC-2026-0268NoneGuest controlled-size host heap allocation through WASIp3 streams
RUSTSEC-2026-0223NonePreemption and traps during bulk operations enable breaking internal VM state
RUSTSEC-2026-0222Low· 3.8Stores can mix up type indices between engines
CVE-2021-39216Medium· 6.3Out-of-bounds read/write and invalid free with `externref`s and GC safepoints in Wasmtime